Tuesday, September 15, 2026 BTC -- / --
🔍

Trezor Data Breach Far Larger Than First Thought, Another 67,000 Customers Affected

Make CryptoTips a preferred source on Google
Trezor Data Breach Far Larger Than First Thought, Another 67,000 Customers Affected
Trezor Data Breach Far Larger Than First Thought, Another 67,000 Customers Affected

The recent data breach at Trezor appears to be significantly larger than initially reported. After customer data from 13,689 people leaked via a shipping partner earlier, Trezor now says a further 67,000 US customers have been affected. That brings the known total to more than 80,000 customers. The incident is not the result of a hack of the hardware wallets or Trezor’s own systems, but of personal data that remained on the systems of shipping partner ShipMonk.

Another 67,000 customers affected

The expansion follows the previously reported data breach at Trezor’s shipping partner. At the time, it emerged that data belonging to 13,689 customers had been exposed.

Trezor now says roughly 67,000 additional US customers are affected. These are people who placed an order between November 2019 and August 2021. Names, email addresses, phone numbers, shipping addresses and order numbers have been exposed.

Based on both reports, at least 80,689 customers are now known to have been affected.

Trezor says it repeatedly asked ShipMonk to delete this customer data during their collaboration. The company says it also received written confirmation that deletion had taken place. The information nonetheless turned out to still be present on ShipMonk’s systems.

Physical security is the main risk

Trezor says it is contacting all 67,000 newly affected customers directly by email. Anyone who does not receive a message does not fall within this new group, according to the company.

The hardware wallets themselves have not been compromised. Trezor says its own systems were not hacked and that its devices remain safe. The risk therefore lies mainly in the misuse of personal information.

A shipping address combined with information indicating that someone has bought a hardware wallet can be particularly sensitive. Criminals could use such data for targeted phishing, fraudulent letters or phone calls. In the most serious cases, knowledge of a crypto owner’s home address can also pose a physical security risk.

That issue has been under discussion for some time. Following the original incident, questions were already being raised about the physical safety of crypto holders. The addition of 67,000 US customers brings that debate back to the fore.

Trezor working on anonymous delivery

Trezor is warning affected users to be extra vigilant about fake messages, phone calls and letters. A wallet backup or seed phrase should never be shared with anyone or entered on a website.

The company is meanwhile working on anonymous delivery for future orders. The aim is to prevent customers’ personal information from being passed on to logistics companies unnecessarily.

Trezor has published more information about the incident on its own website. The expansion makes clear that a hardware wallet can remain technically secure while data surrounding its purchase can still pose a serious security risk.

Summarize this article with AI

Not financial advice. CryptoTips We are not a financial advisor and the content on this website is not financial advice. All information on this website is informative and not a recommendation to buy or sell anything. Consult an expert when making financial decisions and only invest money you can afford. You are responsible for your own investments. We use affiliate referrals and may receive commissions for these. Read our full disclaimer.

Affiliate disclosure. Some links on this site are partner/affiliate links. If you sign up with a partner through such a link, we may receive a commission at no extra cost to you. This never influences our reporting. Read our editorial guidelines.

More News

More news ›